Vulnerabilities (CVE)

Filtered by CWE-89
Total 15527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3254 1 Precoc 1 Precms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action.
CVE-2008-6889 1 Activewebsoftwares 1 Aspreferral 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
CVE-2007-6158 1 Proverbs 1 Proverbs Web Calendar 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname (aka Username) and (2) loginpass (aka Password) parameters to caladmin.php.
CVE-2009-2308 2 Punbb, Punres 2 Punbb, Affiliates Mod 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.
CVE-2008-2556 1 Hessel Brouwer 1 Php Visit Counter 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.
CVE-2008-5292 1 Videogirls 1 Videogirls Biz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.
CVE-2007-4762 1 E-smart Cart 1 E-smart Cart 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092.
CVE-2008-2700 1 Gwm 1 Galatolo Webmanager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6392 1 Dominion Web 1 Dwdirectory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI.
CVE-2008-5632 1 Activewebsoftwares 1 Active Time Billing 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
CVE-2008-4094 1 Rubyonrails 2 Rails, Ruby On Rails 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
CVE-2008-6798 1 Preprojects 1 Pre Real Estate Listings 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
CVE-2009-2400 2 Fijiwebdesign, Joomla 2 Com Php, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
CVE-2008-3588 1 Phsblog 1 Phsblog 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.
CVE-2008-5493 1 Phpstore 2 Wholesale, Wholesales 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3256 1 Siteframe 2 Siteframe Beaumont, Siteframe Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0719 1 Oscommerce 2 Customer Testimonials, Oscommerce 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.
CVE-2009-2339 1 Rentventory 1 Rentventory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via the product parameter.
CVE-2007-6311 1 Falt4 Cms 1 Falt4 Extreme Rc4 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter.
CVE-2009-1323 1 Webfileexplorer 1 Web File Explorer 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.